Lead the content and logic for an autonomous investigation platform: define investigation playbooks, telemetry/schema requirements, disposition and suppression logic, integrate threat intelligence, track quality metrics, and partner with MDR operations to scale ML-driven investigations that replace manual Tier 1-2 triage.
Rapid7 is seeking a Lead Product Manager, AI-SOC to define and execute the strategy powering our autonomous investigation platform. This domain-first role owns everything the investigation agent knows and does, translating deep Detection & Response expertise into a high-impact product roadmap.
About the Team
The AI-SOC product team sits within Rapid7's Detection & Response organization and builds the autonomous investigation platform powering our MDR service. Operating at the intersection of managed security operations and agentic AI, the team develops capabilities that triage alerts at machine speed so analysts can focus on high-value decisions.
About the Role
As a Lead Product Manager, AI-SOC, your primary responsibility will be to own the content layer that determines what the autonomous agent investigates, how it investigates, and what it concludes. Specifically, your focus will be to:
The skills and qualities you'll bring include:
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-TD1 #LI-Remote
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
Rapid7, Inc. is committed to fair and equitable compensation practices. A candidate's salary is determined by various factors including, but not limited to, relevant work experience, skills, and certifications. We evaluate compensation decisions on a case-by-case basis, and it is not typical for an individual to be hired at the very top of the salary range.
The annual salary range for this role, depending on location, is:
United States: $156,200.00 - 211,400.00 USD Annual
Salary ranges may vary based on geographical location. This range does not include variable/incentive compensation, equity and benefits (where applicable/eligible).
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.
About the Team
The AI-SOC product team sits within Rapid7's Detection & Response organization and builds the autonomous investigation platform powering our MDR service. Operating at the intersection of managed security operations and agentic AI, the team develops capabilities that triage alerts at machine speed so analysts can focus on high-value decisions.
About the Role
As a Lead Product Manager, AI-SOC, your primary responsibility will be to own the content layer that determines what the autonomous agent investigates, how it investigates, and what it concludes. Specifically, your focus will be to:
- Define and maintain the full library of investigation playbooks and queries executed across alert types, data sources, and severities, owning the continuous improvement backlog.
- Establish telemetry and schema requirements for onboarding new log sources and alert integrations in direct partnership with engineering and data teams.
- Own the status disposition logic and suppression framework, guiding the evolution from rule-based heuristics to an advanced ML-driven disposition engine.
- Incorporate threat intelligence, including IOC matching, actor context, and TTP enrichment, into autonomous investigation workflows.
- Establish and track core quality metrics, including coverage rate, disposition accuracy, and false positive rates, leveraging feedback loops from MDR analysts.
- Partner with MDR operations to ensure autonomous investigation output consistently meets the quality bar required to replace manual Tier 1-2 triage at scale.
The skills and qualities you'll bring include:
- Bring 7+ years of experience in security operations, alert triage, detection engineering, or security engineering within an MDR, MSSP, or enterprise SOC environment.
- Demonstrate deep working knowledge of Detection & Response across multiple technical domains, including endpoint, network, identity, cloud, or SaaS/email.
- Apply direct experience with major EDR/XDR platforms to write queries, review telemetry, and render defensible disposition decisions.
- Leverage strong proficiency in investigation methodology and the MITRE ATT&CK framework to map alert types to adversary behaviors.
- Demonstrate 2+ years in product management or equivalent SOC leadership where domain expertise was translated into clear engineering requirements.
- Drive efficient decision-making that resolves complex product challenges and enables operational momentum across diverse stakeholder groups.
- Establish clear ownership and accountability for delivery outcomes, quality metrics, and operational commitments.
- Build global cross-functional networks across engineering, data science, and security operations to drive sustainable platform enhancements.
- Act as an active driver of change when transitioning legacy operations toward AI-driven autonomous workflows.
- Bring strong written and verbal communication skills to align cross-functional partners and executive stakeholders around vision and execution.
- Possess US Citizenship with active or prior security clearance experience in federal or government environments.
- Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-TD1 #LI-Remote
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
Rapid7, Inc. is committed to fair and equitable compensation practices. A candidate's salary is determined by various factors including, but not limited to, relevant work experience, skills, and certifications. We evaluate compensation decisions on a case-by-case basis, and it is not typical for an individual to be hired at the very top of the salary range.
The annual salary range for this role, depending on location, is:
United States: $156,200.00 - 211,400.00 USD Annual
Salary ranges may vary based on geographical location. This range does not include variable/incentive compensation, equity and benefits (where applicable/eligible).
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.
Similar Jobs at Rapid7
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Lead the global PMO to align product roadmaps and engineering delivery, embed agile operating models within squads, manage capacity and metrics, mitigate development risks, and accelerate time-to-market for cloud-native enterprise cybersecurity products.
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Lead Rapid7's global quality engineering strategy, scaling distributed teams and embedding automated, AI-driven validation across cloud-native CI/CD pipelines. Drive tooling consolidation, reliability metrics, advanced automation (chaos engineering, synthetic data, intelligent test orchestration), cross-functional alignment, and release readiness to accelerate product delivery and resilience.
Top Skills:
AIAutomated TestingAutomation FrameworksChaos EngineeringCloud-NativeContinuous Delivery PipelinesContinuous DeploymentContinuous IntegrationIntelligent Test OrchestrationSynthetic Data Generation
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Lead Rapid7's multi-year AI strategy and roadmap across product and operations, build and run a high-performing AI organization, drive LLM, generative and agentic capabilities, integrate threat intelligence for security detection and prioritization, establish MLOps and responsible AI governance, and represent Rapid7 externally while partnering with Sales, SOC, and Customer Success to deliver measurable business outcomes.
Top Skills:
Agentic SystemsAi ObservabilityCloud Ai PlatformsGenerative AiLarge Language ModelsMachine Learning FrameworksMlopsModel MonitoringPrompt EngineeringRetrieval-Augmented Generation (Rag)
What you need to know about the NYC Tech Scene
As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.
Key Facts About NYC Tech
- Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
- Key Industries: Artificial intelligence, Fintech
- Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
- Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

